CVE detail
CVE-2026-56355
GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 18.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
No excerpt available.
referencewww.mallory.aiJun 20, 2026, 9:16 PM- https://www.hacktron.aiwww.hacktron.ai
No excerpt available.
referencewww.hacktron.aiJun 20, 2026, 9:16 PM No excerpt available.
referencewww.fsf.orgJun 20, 2026, 9:16 PM- https://news.ycombinator.com/item?id=48605220news.ycombinator.com
No excerpt available.
Issue Trackingnews.ycombinator.comJun 20, 2026, 9:16 PM - https://cgit.git.savannah.gnu.org/cgit/administration/savane.git/tree/frontend/php/file.php?h=release-3.17#n123cgit.git.savannah.gnu.org
No excerpt available.
Patchcgit.git.savannah.gnu.orgJun 20, 2026, 9:16 PM - https://cgit.git.savannah.gnu.org/cgit/administration/savane.git/tree/frontend/php/file.php?h=release-3.17#n113cgit.git.savannah.gnu.org
No excerpt available.
Patchcgit.git.savannah.gnu.orgJun 20, 2026, 9:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-14169CVSS 8.1 · High
Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could resu…
- CVE-2026-49318CVSS 1.0 · Low
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the…
- CVE-2026-49317CVSS 1.0 · Low
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the…
- CVE-2026-44919CVSS 4.3 · Medium
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.
- CVE-2026-45033CVSS 8.5 · High
GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security vulnerability has been identified in GitHub Copilot CLI where a…
- CVE-2026-44600CVSS 3.7 · Low
Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-2026-010.